hashkitten (@hash_kitten) 's Twitter Profile
hashkitten

@hash_kitten

vulnerability research @assetnote // hacking // codegolf // ctf with 🛹🐶

ID: 778864815385157632

calendar_today22-09-2016 07:53:37

14 Tweet

1,1K Takipçi

172 Takip Edilen

joseph (@josep68_) 's Twitter Profile Photo

Finished Google CTF 2021 at #13 with 🛹🐻 GG to everyone involved! crypto writeups (all challenges): jsur.in/posts/2021-07-…

Finished Google CTF 2021 at #13 with 🛹🐻 GG to everyone involved!

crypto writeups (all challenges): jsur.in/posts/2021-07-…
PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

Just learned you can exploit blind file-reads in PHP by combining the dechunk filter with the PHP memory limit. This crazy finding by hashkitten is a great reminder to pay attention to CTF writeups! github.com/DownUnderCTF/C…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Did you enjoy the latest blogpost on PHP filter chains? Well, our ninja Remsio strikes again with a new article detailing how you can abuse them to leak files from the targeted system, as well as a freshly developed tool to exploit it! synacktiv.com/publications/p…

hashkitten (@hash_kitten) 's Twitter Profile Photo

I've written another set of challenges this year and I'm really happy with how they turned out. Make sure you check out DUCTF this weekend :)

shubs (@infosec_au) 's Twitter Profile Photo

At Assetnote, we published our research on Magento's pre-authentication XXE (CVE-2024-34102). hashkitten and I reproduced this issue together. It is a brilliant vulnerability originally found by Sergey Temnikov. You can read our research here: assetnote.io/resources/rese…

At <a href="/assetnote/">Assetnote</a>, we published our research on Magento's pre-authentication XXE (CVE-2024-34102). <a href="/hash_kitten/">hashkitten</a> and I reproduced this issue together. It is a brilliant vulnerability originally found by Sergey Temnikov. You can read our research here: assetnote.io/resources/rese…
shubs (@infosec_au) 's Twitter Profile Photo

Our security researcher hashkitten found one of the most critical exploit chains in the history of Assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…

Our security researcher <a href="/hash_kitten/">hashkitten</a> found one of the most critical exploit chains in the history of <a href="/assetnote/">Assetnote</a>. Affecting 40k+ instances of ServiceNow, we could  execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…
shubs (@infosec_au) 's Twitter Profile Photo

We discovered a pre-authentication RCE vulnerability in Craft CMS caused by an obscure PHP foot gun (CVE-2024-56145), approx 150k sites created with Craft CMS. You can read @Assetnote's Security Research team's blog on the issue: assetnote.io/resources/rese… #attacksurfacemanagement

We discovered a pre-authentication RCE vulnerability in Craft CMS caused by an obscure PHP foot gun (CVE-2024-56145), approx 150k sites created with Craft CMS.

You can read @Assetnote's Security Research team's blog on the issue: assetnote.io/resources/rese…

#attacksurfacemanagement
shubs (@infosec_au) 's Twitter Profile Photo

To kick off our Christmas and July research posts, we explain how we achieved persistent XSS on every Adobe Experience Manager Cloud instance, not twice, but thrice! This is now patched across all of AEM cloud, but what an interesting attack surface! slcyber.io/assetnote-secu…

To kick off our Christmas and July research posts, we explain how we achieved persistent XSS on every Adobe Experience Manager Cloud instance, not twice, but thrice! This is now patched across all of AEM cloud, but what an interesting attack surface! slcyber.io/assetnote-secu…
BSidesCanberra (@bsidescbr) 's Twitter Profile Photo

Pre-auth bugs in enterprise software? Yes please. hashkitten takes us inside their research on Adobe Experience Manager—uncovering critical, pre-auth vulnerabilities in a platform powering 45,000+ sites. Live at BSides Canberra 2025: cfp.bsidescbr.com.au/bsides-canberr…

shubs (@infosec_au) 's Twitter Profile Photo

This month's Christmas in July release from Searchlight Cyber's Security Research team is a pre-authentication RCE vulnerability in Sawtooth Lighthouse Studio (CVE-2025-34300). This software is prevalent and hidden in plain sight. Read more on our blog: slcyber.io/assetnote-secu…

This month's Christmas in July release from <a href="/SLCyberSec/">Searchlight Cyber</a>'s Security Research team is a pre-authentication RCE vulnerability in Sawtooth Lighthouse Studio (CVE-2025-34300). This software is prevalent and hidden in plain sight. Read more on our blog: slcyber.io/assetnote-secu…
Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

Turns out my #PHRACK article is live! 🔥 > The Art of PHP — My CTF Journey and Untold Stories! Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to [email protected] for not forgetting me, TMZ for the edits, and the

Turns out my #PHRACK article is live! 🔥

&gt; The Art of PHP — My CTF Journey and Untold Stories!

Kinda a love letter to those CTF players &amp; PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to <a href="/0xdea/">raptor@infosec.exchange</a> for not forgetting me, <a href="/guitmz/">TMZ</a> for the edits, and the
skateboarding dog (@sk8boardingdog) 's Twitter Profile Photo

LET'S GET THE BALL (BEARINGS) ROLLING ONLY 4 WEEKS LEFT UNTIL SKATEBOARDING DOG CTF BSidesCanberra 2025 WATCH THE COUNTDOWN ON OUR WEBSITE: 2025.sk8.dog

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

Two weeks ago, I did my first (in-person) HackerOne LHE in Singapore! I worked with hashkitten and shubs, and I'm really happy with how it went and what we found :D (We won the Best Team and Best Bug awards! 🔥) It was an amazing event, thanks HackerOne! 😁